Research Article

Real-Time Malware Process Detection and Automated Process Killing

Table 8

Summary of process killing models, validation and test set score metrics [Table 1 of 3].

ModelValTest
f1tnrtprf1tnrtpr

AdaBoostModel_glo_pro77.5855.4691.6067.0449.8088.67
AdaBoostModel_glo_pro mean process tree78.0155.4692.4466.7550.4887.59
AdaBoostModel_glo_pro process tree min alerts: 178.8755.4694.1262.2934.0390.35
AdaBoostModel_glo_pro process tree min alerts: 278.8755.4694.1262.2934.0390.35
AdaBoostModel_glo_pro process tree min alerts: 378.8755.4694.1262.2934.0390.35
AdaBoostModel_glo_pro process tree min alerts: 478.8755.4694.1262.2934.0390.35
AdaBoostModel_glo_pro rolling mean window: 279.2270.5984.8769.5760.8884.88
AdaBoostModel_glo_pro rolling mean window: 379.3772.2784.0369.5961.5384.39
AdaBoostModel_glo_pro rolling mean window: 480.6780.6780.6768.4467.8077.34
AdaBoostModel_glo_pro sum alerts min: 280.6678.1582.3569.3566.5879.89
AdaBoostModel_glo_pro sum alerts min: 381.2083.1979.8367.8370.9273.88
AdaBoostModel_glo_pro sum alerts min: 480.8784.8778.1565.9273.3269.00
AdaBoostModel_pro75.3447.0692.4465.6445.7988.89
AdaBoostModel_pro mean process tree75.8648.7492.4465.7447.8387.59
AdaBoostModel_pro process tree min alerts: 175.6845.3894.1260.3126.4691.17
AdaBoostModel_pro process tree min alerts: 275.6845.3894.1260.3126.4691.17
AdaBoostModel_pro process tree min alerts: 375.6845.3894.1260.3126.4691.17
AdaBoostModel_pro process tree min alerts: 475.6845.3894.1260.3126.4691.17
AdaBoostModel_pro rolling mean window: 278.0364.7186.5569.3559.6385.47
AdaBoostModel_pro rolling mean window: 377.9967.2384.8768.9159.2084.99
AdaBoostModel_pro rolling mean window: 480.8379.8381.5169.0166.4479.40
AdaBoostModel_pro sum alerts min: 281.1275.6384.8767.9161.0681.68
AdaBoostModel_pro sum alerts min: 381.1780.6781.5166.6464.9776.42
AdaBoostModel_pro sum alerts min: 479.6680.6778.9964.2568.1270.14
AdaBoostModel_pro_tree75.0847.7394.9664.1230.5886.60
AdaBoostRegression_pro_process56.63100.0039.5015.0697.928.40
DTModel_glo_pro84.5371.4394.1271.4158.1990.62
DTModel_glo_pro mean process tree85.9373.9594.9671.4959.4889.70
DTModel_glo_pro process tree min alerts: 184.6470.5994.9665.5942.4291.27
DTModel_glo_pro process tree min alerts: 284.6470.5994.9665.5642.3491.27
DTModel_glo_pro process tree min alerts: 384.6470.5994.9665.5642.3491.27
DTModel_glo_pro process tree min alerts: 484.6470.5994.9665.5642.3491.27
DTModel_glo_pro rolling mean window: 288.7088.2489.0875.0970.4986.94
DTModel_glo_pro rolling mean window: 387.8787.3988.2474.5769.7786.61
DTModel_glo_pro rolling mean window: 489.0893.2885.7174.0474.2981.63
DTModel_glo_pro sum alerts min: 289.7491.6088.2475.4872.6485.69
DTModel_glo_pro sum alerts min: 389.4794.1285.7174.0075.6280.38
DTModel_glo_pro sum alerts min: 488.3994.9683.1970.1977.3072.63
DTModel_pro89.7682.3595.8071.5356.5492.25
DTModel_pro mean process tree90.9184.0396.6472.1359.3891.06
DTModel_pro process tree min alerts: 190.2082.3596.6464.4537.0492.79
DTModel_pro process tree min alerts: 290.2082.3596.6464.4236.9792.79
DTModel_pro process tree min alerts: 390.2082.3596.6464.4236.9792.79
DTModel_pro process tree min alerts: 490.2082.3596.6464.4236.9792.79
DTModel_pro rolling mean window: 293.1694.9691.6073.8266.1988.40
DTModel_pro rolling mean window: 391.7794.9689.0873.4966.1587.80
DTModel_pro rolling mean window: 490.7595.8086.5572.0569.3882.38
DTModel_pro sum alerts min: 292.1795.8089.0873.4367.4486.56
DTModel_pro sum alerts min: 390.7595.8086.5571.5369.6381.25
DTModel_pro sum alerts min: 489.2995.8084.0367.5870.8173.55
DTModel_pro_tree85.9373.4897.4870.4043.0291.57
DTRegression_pro_process89.0680.6795.8071.6257.9891.22
GBDTModel_glo_pro80.4463.8791.6072.6259.7391.71
GBDTModel_glo_pro mean process tree80.8863.8792.4472.7660.6391.22
GBDTModel_glo_pro process tree min alerts: 181.7563.8794.1266.3243.2892.14
GBDTModel_glo_pro process tree min alerts: 281.7563.8794.1266.3243.2892.14
GBDTModel_glo_pro process tree min alerts: 381.7563.8794.1266.3243.2892.14
GBDTModel_glo_pro process tree min alerts: 481.7563.8794.1266.3243.2892.14
GBDTModel_glo_pro rolling mean window: 285.1283.1986.5576.0671.5087.80
GBDTModel_glo_pro rolling mean window: 384.5284.0384.8775.8771.8287.15
GBDTModel_glo_pro rolling mean window: 484.1286.5582.3575.2576.6981.57
GBDTModel_glo_pro sum alerts min: 284.8784.8784.8776.4675.6584.66
GBDTModel_glo_pro sum alerts min: 385.2289.0882.3574.1278.7777.78
GBDTModel_glo_pro sum alerts min: 484.4490.7679.8371.9981.1072.30
GBDTModel_pro80.7362.1893.2871.3158.0990.51
GBDTModel_pro mean process tree82.0564.7194.1271.7659.5990.14
GBDTModel_pro process tree min alerts: 180.7159.6694.9664.8840.3491.33
GBDTModel_pro process tree min alerts: 280.7159.6694.9664.8740.3091.33
GBDTModel_pro process tree min alerts: 380.7159.6694.9664.8740.3091.33
GBDTModel_pro process tree min alerts: 480.7159.6694.9664.8740.3091.33
GBDTModel_pro rolling mean window: 284.6879.8388.2475.0871.6085.91
GBDTModel_pro rolling mean window: 384.0880.6786.5574.9971.7185.64
GBDTModel_pro rolling mean window: 484.3984.8784.0373.9176.0579.84
GBDTModel_pro sum alerts min: 285.4884.0386.5574.5074.4082.33
GBDTModel_pro sum alerts min: 385.1186.5584.0372.3576.7776.59
GBDTModel_pro sum alerts min: 483.8488.2480.6770.1778.3871.71
GBDTModel_pro_tree79.0259.0994.9671.0846.6890.51
GBDTRegression_pro_process89.7187.3991.6071.8480.5772.52
MLPModel_glo_pro66.6713.4593.2857.9219.0090.68
MLPModel_glo_pro mean process tree67.4816.8193.2859.7925.7490.51
MLPModel_glo_pro process tree min alerts: 167.4613.4594.9657.6117.6490.84
MLPModel_glo_pro process tree min alerts: 267.4613.4594.9657.6117.6490.84
MLPModel_glo_pro process tree min alerts: 367.4613.4594.9657.6117.6490.84
MLPModel_glo_pro process tree min alerts: 467.4613.4594.9657.6117.6490.84
MLPModel_glo_pro rolling mean window: 267.9628.5788.2458.7332.2084.17
MLPModel_glo_pro rolling mean window: 367.7934.4584.8758.9034.3183.20
MLPModel_glo_pro rolling mean window: 468.7541.1883.1958.3240.5578.16
MLPModel_glo_pro sum alerts min: 268.9438.6684.8759.5139.1981.30
MLPModel_glo_pro sum alerts min: 369.0445.3881.5158.4743.1776.80
MLPModel_glo_pro sum alerts min: 470.6353.7879.8357.2347.7271.76